CVE-2026-90880: D-Link DSL-3782 Diagnostics Diagnostics.asp system command injection
A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/NewGUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must have low-level privileges on the affected device, but exploitation can be initiated remotely and does not require user interaction.
Which input should defenders focus on when investigating exposure?
The vulnerable path is the Addr argument handled by the system function in /cgi-bin/New_GUI/Set/Diagnostics.asp within the Diagnostics component. Review access to this endpoint and any requests containing unexpected shell metacharacters or command-like content in Addr.
Is public exploit code available?
Yes. The exploit has been publicly released, which increases the likelihood of attempted attacks against reachable affected devices.